Cybersecurity / Capital Markets

SC Technology Risk Management Review

The SC's Guidelines on Technology Risk Management replaced the old cyber risk guidelines in 2024 and added near-miss reporting, pre-deployment security assessment and penetration testing of critical systems. We review your compliance and evidence against them.

Against the Guidelines on Technology Risk Management, revised 19 August 2024 Near-miss reporting and pre-deployment gates Ready for an SC-appointed review
Overview

SC Technology Risk Management Review

What it is

A compliance review of a capital market entity's technology risk governance, processes and evidence against the SC guidelines. It reviews whether required testing happens and is evidenced; it does not perform the testing itself.

Why organisations need it

The guidelines apply to capital market entities including fund managers, brokers, platform operators and trustees. The 2024 revision requires near-miss reporting, a cyber security assessment before deploying a system, penetration testing before deploying new critical systems, and allows the SC to appoint an independent party to review compliance. Many entities have policies but not the evidence.

Key features

What the engagement covers

Board and management

Oversight and accountability.

Change and deployment

Pre-deployment assessments and testing gates.

Third parties and cloud

Oversight of providers.

Incidents and near misses

Identification and reporting to the SC.

AI and ML use

Ethical use guidance.

Evidence

Records an SC-appointed reviewer would request.

Business value

What the business gets out of it

Ready for scrutiny

Evidence in place.

Current guidelines

The 2024 revision, not the old cyber rules.

Practical gates

Release processes that comply.

Board confidence

Independent view.

Mid-level scope

Compliance review, no intrusive testing.

How it works

How the engagement runs

01

Scoping

Entity and systems.

02

Document review

Policies and records.

03

Walkthroughs

Change, incident and third-party processes.

04

Gap analysis

Against the guidelines.

05

Report

Findings and plan.

Deliverables

What you receive

Review report

Findings by risk.

Guideline mapping

Requirement by requirement.

Near-miss procedure

Draft or review.

Remediation plan

Owners and dates.

Board summary

Position for directors.

Who it is for

Who this is built for

Industries

Fund managersStockbrokersInvestment banksTrusteesCrowdfunding and digital asset platforms

Company sizes

Capital market entities

Departments

TechnologyRiskComplianceBoard
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Which guidelines apply?

The SC Guidelines on Technology Risk Management, issued 1 August 2023 and revised 19 August 2024, which replaced the 2016 cyber risk guidelines.

Do you perform penetration testing?

No. We review whether required testing happens and is evidenced. Testing is performed by licensed providers.

What is a near-miss event?

An event that could have caused an incident but did not. The guidelines require reporting them to the SC.

Is this the same as an SC-appointed review?

No. The SC appoints its own reviewer. This prepares you for one.

How long does it take?

Typically three to six weeks.

Get started

Review your technology risk compliance

Tell us your entity type and key systems. We will scope and quote.